Jump to content

Staff question - why do you have access to my password?


Recommended Posts

Posted

A member of staff asked the computing head this lunchtime in the canteen, I wasn't there at the time but he was questioning why I (as network manager) have access to all staff usernames and passwords.

 

I've written a short explanation which I'm puting up on the schools intranet, I'm sure most staff aren't in the slightest interested in it, but there's always someone. Fact is I can't be bothered to look through everyones files, send emails as them or browse dodgy websites in order to get them into trouble... it would risk my job for starters and I have better things to do!

 

Here is roughly what I've written although it might change and I'll have to * some things out :p

Staff internet, e-mail and network passwords are accessable by only one member of staff - the network manager (NM). The network manager by default has access to each and every folder, file and device on every networked computer within the school, there are no files that the NM cannot access, delete, copy or edit. This is an operational need and is the case in every network and in every organisation. There is simply always someone who has to have access to everything.

 

A NM does not need your username or password to access your files.

 

In addition, the NM also has access to usernames and passwords for all users on the network, so what prevents a NM from abusing his/her position?

 

Simple:

 

Whenever anyone, including the NM access any web page from within the school the follow details are recorded:

 

1. Username of the person accessing the page.

2. Date/time of access.

3. Computer that the access was made from. (Important for tracing people).

 

In addition when you send an e-mail it records the date/time and the IP address of the computer that it was sent from and displays there in the header of the e-mail, these IP addresses are unique within the council and can allow the NM/I.T. Services to pin down a computer sending virus/fakes/malicious e-mails within seconds.

 

So what prevents a NM from modifying your files for a joke?

 

Short answer - nothing. Any NM will have the knowledge to spoof, fake, hack or otherwise alter a file with ease and make it appear that it has been done by someone else. The simple fact is that the NM is hired because of his/her knowledge of computers and as such the council has to put a certain amount of faith in his or her integrity. I.T. staff in general don't find peoples files particularly exciting, they spend long enough looking at a computer screen without doing so for fun.

 

Any member of staff who wishes me to remove their password need merely ask and I will, however please remember that this may mean contacting I.T. services and a 5-7 day wait if you forget it at a future date. I.T. services only usually deal with the NM as the schools point of contact and as such only the NM can log faults or account changes with them, you may however contact I.T. services yourself on *********** if you would like to change your password, however ironically, you will have to them tell the NM what your password is to enable you to access the network.

 

Staff passwords (and I only have about 60% of staffs passwords anyway) are held in one file, which is encrypted and held within my own folder on the server. Nobody else in this school can ever gain access to this folder, only I.T. services and the NM can.

 

comments? :o

Posted

I as network manager do not (and don't wish to have) access to any staff or students passwords.

 

If they forget their password I will reset it and force the user to cahnge it next time they logon.

 

All staff and students are responsable for thier own accounts and not knowing thier passwords removes the possibility if blame !

Posted

We just tell them it's one-way encrpytion and it is impossible to 'read' their passwords - we can only reset them.

 

But also make it clear that we don't need their password to access their personal area.

Posted

I only have them as the central I.T. department more or less refuse to deal with teachers directly in secondary schools. As such I have to be e-mailed the passwords.

 

I have absolutely no need for them, don't particularly want them however several of them have asked me to "keep note" of the passwords as they tend to forget them after holidays and it prevents them writing them down and placing them in their desks (anyone else noticed this?).

 

I don't particularly like having them sent to me but sadly it's out of my control because it's done at the I.T. services department.

Posted

Its always best not to know staff passwords.

 

I just tell everybody that I cannot see their passwords, the only thing I can do is reset them, and require them to change them at first logon.

Posted
Why do you have their passwords? I just change them on the server if they forget them

 

The network, internet and e-mail servers don't share passwords, it's annoying but I.T. services (councils central department) won't or hasn't managed to get it all integrated yet.

 

Eventually the internet and network login passwords will be the same (so I can let staff change them anytime) but at the moment the network passwords are locked so they can't alter them.

 

Some staff have problems remembering one password, which doesn't expire and frankly would never remember two or three that had 2/3 month expiry dates set (what I'd like to do..).

Posted
I only have them as the central I.T. department more or less refuse to deal with teachers directly in secondary schools. As such I have to be e-mailed the passwords.

 

They email you the passwords?? ....oh dear... :?

Posted

When I was at college, the passwords for students were generated by the IT Team and given to them when they joined.

 

Due to the amount of people that 'forget' their password, when the passwords were generated at the beginning of each year, they were also printed off and handed to the support desk in the learning centre.

 

This way, any student that forgets their password only needs to go to the support desk in the learning centre to be told what it is. The support desk in the learning centre was separate to IT Support, so IT Support were rarely bothered about forgotten passwords. It must have saved them a lot of time.

Posted
I only have them as the central I.T. department more or less refuse to deal with teachers directly in secondary schools. As such I have to be e-mailed the passwords.

 

They email you the passwords?? ....oh dear... :?

 

Yup and it's something I've been pulling my hair of over for years. Not only that they have in the pass called me to tell me a password, got another member of staff and told them the password. It's pathetic at times.

 

Sadly because of the way things are currently setup I've no choice but to access e-mailed passwords.

 

I'm due to have my 2003 domain clustered later this year (when god only knows) and at that time I'll be able to get people to reset their network and internet passwords, which should HOPEFULLY sort this situation out.

 

However it'll remain the same for pupils as apparently they'll never be allowed to change their own passwords :o

Posted

So you don't run your own AD then?

 

I just tell staff that I can not see their password, I just change it and force them to change on log on.

Posted
Is this some kind of joke? Or should this be published on "Worse than Failure" (formally thedailywtf)

 

http://worsethanfailure.com/Articles/Twice_Annual_About_Security.aspx

 

You could publish the fact that when I report a member of staff isn't able to access e-mail or internet the I.T. services helpdesk will knock it back to me 80% of the time if I don't include the original password( which I shouldn't have! )

 

What's really a killer for me though is that staff in the school might get annnoyed at my knowing their passwords (well having them in a file) yet some regularly leave their classroom PCS left on and logged in as themself then go on holiday or go home. :)

Posted
What's really a killer for me though is that staff in the school might get annnoyed at my knowing their passwords (well having them in a file) yet some regularly leave their classroom PCS left on and logged in as themself then go on holiday or go home. :)

 

Sorry but I would have to leave as you can not be expected to manage a network like that. Infact it's not really managing anything really.

Posted
the key point in all of this was well made with one word 'Integrity' it sounds like yours is being questioned halfmad. Although i wouldn't take it personally some people have nothing better to do than winge, your explanation is clear and concise but not neccassary (in my opinion) your hired to to do a job, your computing head should have set the record straight for you.
Posted
Maybe you could highlight that you wish there were no need for you to have their passwords but that because of the way the LA do things you need the information to get their issues resolved as soon as possible. Sounds like the LA need to pull their fingers out and sort something. I hate it when quick and dirty workarounds get left in place because it's "easier".
Posted

Yeah I've raised it with them back in December after they let it go on for 3 months without any plan or schedule. I wouldn't leave my job over something like this unless I was accused of something and only then after being proven innocent. Staff in the schools I manage are pretty nice but there are always new staff who wonder why things are done in a different way and I'm giving them the benefit of doubt and saying that it's merely curiosity :)

 

I hope to have things sorted out, 2003 clustering will do it as then they can change their passwords all day if they really want to! Ultimately though I'm trying to get across that I don't need their access details to get to their files, to report on what they are accessing on the internet etc.

 

Disease - it's not managing accounts which frankly is a tiny part of my job, to be honest it's something that a technician could do with his/her hands tied behind their back anyway but the fact is that it SHOULD be necessary, we should have to reset the "change password at next login" option now and then. It's only laziness on IT services part that's preventing me from doing so.

Posted

Oddly thinking back to the time when I was working in the I.T. department I had to change my password every month and I had access to less vital data than I do now (and I only change my password because of habit). Yet staff, who have access to some rather detailed kids data can have the same password for 10+ years, it seems rather odd!

 

think I'll query this with the education department and get them to put pressure on the IT department!

Posted
Have you considered doing what we've done and gone completely independant from the county for the curriculum side? As they sound like a shambles and a half and I would probably walk out of that place after a few weeks if I had no control.
Posted
Ultimately though I'm trying to get across that I don't need their access details to get to their files, to report on what they are accessing on the internet etc.

 

I find it hard to believe that people can think that a system administrator of a network does not have 100% access to that network and even harder to believe that they can get annoyed about it when they find out the truth. Probably the only sysadmins in the world that can operate a network without full access are people who work for organisations like the NSA and MI6.

Posted

This entire thing sounds like a bit of a breach of the Data Protection Act to me... Having passwords - which can be used to get to pupil data - available in text format in this manner, especially being sent via email.

 

If anyone is leaving passwords lying around in drawers I would inform them that this is also a breach of the DPA.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...